Checkmarx One vs Fortify on Demand comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 24, 2022
 

Categories and Ranking

Checkmarx One
Ranking in Application Security Tools
3rd
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.6
Number of Reviews
68
Ranking in other categories
Vulnerability Management (12th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Fortify on Demand
Ranking in Application Security Tools
8th
Ranking in Static Application Security Testing (SAST)
9th
Average Rating
8.0
Number of Reviews
58
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Application Security Tools category, the mindshare of Checkmarx One is 13.0%, down from 15.4% compared to the previous year. The mindshare of Fortify on Demand is 4.8%, up from 4.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
Unique Categories:
Static Application Security Testing (SAST)
11.1%
Vulnerability Management
0.6%
 

Featured Reviews

AS
Feb 22, 2023
The report function is a great, configurable asset but sometimes yields false positives
Our company uses the solution to check the vulnerabilities in our products at the build level. We capture, identify potential issues and fixes, and publish reports on a weekly basis.  We work in the banking industry and have a license for 100 users The report function is the solution's greatest…
AM
Oct 31, 2023
A highly trusted and comprehensive application security testing solution, known for its seamless integration, advanced technical capabilities, and reliability
We use it to scan the bank's applications systematically. This process aims to identify and address security vulnerabilities within the applications, ensuring the robustness of our security measures It stands out by generating fewer false positives which has a distinct advantage, as it translates…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
"What I like best about Checkmarx is that it has fewer false positives than other products, giving you better results."
"The most valuable features of Checkmarx are difficult to pinpoint because of the way the functionalities and the features are intertwined, it's difficult to say which part of them I prefer most. You initiate the scan, you have a scan, you have the review set, and reporting, they all work together as one whole process. It's not like accounting software, where you have the different features, et cetera."
"One of the most valuable features is it is flexible."
"Apart from software scanning, software composition scanning is valuable."
"We use the solution for dynamic application testing."
"It shows in-depth code of where actual vulnerabilities are."
"The most valuable features of Checkmarx are the Best Fix Location and the Payments option because you can save a lot of time trying to mitigate the configuration. Using these tools can save you a lot of time."
"Fortify helps us to stay updated with the newest languages and versions coming out."
"Being able to reduce risk overall is a very valuable feature for us."
"One of the top features is the source code review for vulnerabilities. When we look at source code, it's hard to see where areas may be weak in terms of security, and Fortify on Demand's source code review helps with that."
"The solution is user-friendly."
"The most important feature of the product is to follow today's technology fast, updated rules and algorithms (of the product)."
"The scanning capabilities, particularly for our repositories, have been invaluable."
"The feature that I find the most useful is being able to just see the vulnerabilities online while checking the code and then checking suggestions for fixing them."
"The most valuable feature is that it connects with your development platforms, such as Microsoft Information Server and Jira."
 

Cons

"Checkmarx could be improved with more integration with third-party software."
"I can't create a business case with multiple-factor authentication."
"This product requires you to create your own rulesets. You have to do a lot of customization."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"Checkmarx could improve by reducing the price."
"Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"We can run only one project at a time."
"The products must provide better integration with build tools."
"The technical support is actually a problem that needs to be addressed. Since the acquisition and merger with Hewlett Packard, it has been really hard to know who the technical or salesperson to talk to."
"There is room for improvement in the integration process."
"It could have a little bit more streamlined installation procedure. Based on the things that I've done, it could also be a bit more automated. It is kind of taking a bunch of different scanners, and SSC is just kind of managing the results. The scanning doesn't really seem to be fully integrated into the SSC platform. More automation and any kind of integration in the SSC platform would definitely be good. There could be a way to initiate scans from SSC and more functionality on the server-side to initiate desk scans if it is not already available."
"The solution has some issues with latency. Sometimes it takes a while to respond. This issue should be addressed."
"Fortify on Demand needs to improve its pricing."
"We typically do our bulk uploads of our scans with some automation at the end of the development cycle but the scanning can take a lot of time. If you were doing all of it at regular intervals it would still consume a lot of time. This could procedure could improve."
"It does scanning for all virtual machines and other things, but it doesn't do the scanning for containers. It currently lacks the ability to do the scanning on containers. We're asking their product management team to expand this capability to containers."
 

Pricing and Cost Advice

"It is an expensive solution."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"The interface used to create custom rules comes at an additional cost."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"We have purchased an annual license to use this solution. The price is reasonable."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"We used the one-time application, Security Scan Dynamic. I believe the original fee was $8,000."
"Fortify on Demand is affordable, and its licensing comes with a year of support."
"Buying a license would be feasible for regular use. For intermittent use, the cloud-based option can be used (Fortify on Demand)."
"The product's cost depends on the type of license."
"The price is fair compared to that of other solutions."
"Fortify on Demand is moderately priced, but its pricing could be more flexible."
"We make an annual purchase of the licenses we need."
"It is quite expensive. Pricing and the licensing model could be improved."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
10%
Government
5%
Financial Services Firm
19%
Computer Software Company
14%
Manufacturing Company
12%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What do you like most about Micro Focus Fortify on Demand?
It helps deploy and track changes easily as per time-to-time market upgrades.
What is your experience regarding pricing and costs for Micro Focus Fortify on Demand?
Fortify on Demand is more expensive than Burpsuite. I rate its pricing a nine out of ten.
What needs improvement with Micro Focus Fortify on Demand?
The product has a lot of false positives. If the outputs can have fewer false positives, then that will be the greatest benefit the tool can offer.
 

Comparisons

 

Also Known As

No data available
Micro Focus Fortify on Demand
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
SAP, Aaron's, British Gas, FICO, Cox Automative, Callcredit Information Group, Vital and more.
Find out what your peers are saying about Checkmarx One vs. Fortify on Demand and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.